Apr 29, 2026 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Phpmyfaq: public exploit or PoC linked (privilege escalation)
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Active exploit activity

CVE-2025-32432 Craft CMS Code Injection

  • Public exploit or PoC available
  • Exploit activity linked
  • Remote code execution exposure

Craft CMS RCE now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Active exploit activity

CVE-2025-69210 FacturaScripts is open-source enterprise resource planning and accounting software.

  • Public exploit or PoC available
  • Exploit activity linked

Facturascripts XSS now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Critical exposure

CVE-2026-26015 DocsGPT is a GPT-powered chat for documentation.

  • CVSS 10
  • Remote code execution exposure

New critical Arc53 Docsgpt RCE (CVSS 10) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

CVE-2024-30167 Exploit

/cgi-bin/time.cgi in Atlona AT-OME-MS42 Matrix Switcher 1.1.2 allow remote authenticated users to execute arbitrary commands as root via...

CVE-2026-24421 Exploit

phpMyFAQ is an open source FAQ web application.

CVE-2026-22704 Exploit

HAX CMS helps manage microsite universe with PHP or NodeJs backends.

CVE-2026-22241 Exploit

The Open eClass platform (formerly known as GUnet eClass) is a complete course management system.

CVE-2025-69210 Exploit

FacturaScripts is open-source enterprise resource planning and accounting software.

CVE-2025-68664 Exploit

LangChain is a framework for building agents and LLM-powered applications.

CVE-2025-12744 Exploit

A flaw was found in the ABRT daemon’s handling of user-supplied mount information.ABRT copies up to 12 characters from an untrusted input...

CVE-2025-60751 Exploit

GeographicLib 2.5 is vulnerable to Buffer Overflow in GeoConvert DMS::InternalDecode.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2018-25316 CVSS 9.3

Tenda W308R v2 V5.07.48 contains a cookie session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by...

CVE-2018-25317 CVSS 9.3

Tenda W3002R/A302/W309R wireless routers version V5.07.64_en contain a cookie session weakness vulnerability that allows unauthenticated...

CVE-2018-25318 CVSS 9.3

Tenda FH303/A300 firmware V5.07.68_EN contains a session weakness vulnerability that allows unauthenticated attackers to modify DNS setti...

CVE-2026-26015 CVSS 10

DocsGPT is a GPT-powered chat for documentation.

Wazuh is a free and open source platform used for threat prevention, detection, and response.

CVE-2026-36841 CVSS 9.8

TOTOLINK N200RE V5 was discovered to contain a command injection vulnerability via the macstr and bandstr parameters in the formMapDelDev...

CVE-2026-38992 CVSS 9.8

Cockpit v2.13.5 and earlier is vulnerable to arbitrary code execution via the filter parameter within multiple endpoints.

CVE-2026-41940 CVSS 9.3

WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function

CVE-2026-5166 CVSS 9.6

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in TUBITAK BILGEM Software Technologies Rese...

CVE-2026-7381 CVSS 9.1

Plack::Middleware::XSendfile versions through 1.0053 for Perl can allow client-controlled path rewriting.

View critical disclosures

cvelogic Threat Intelligence